CVE-2023-1977: Oplugins Booking Manager
High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.
The Booking Manager WordPress plugin before 2.0.29 does not validate URLs input in it's admin panel or in shortcodes for showing events from a remote .ics file, allowing an attacker with privileges as low as Subscriber to perform SSRF attacks on the sites internal network.
Affected products
- Oplugins Booking Manager: before 2.0.29 (fixed in 2.0.29)
Published 2023-08-16. Last modified 2026-06-17.